Skip to content

PKARR

Markdown

PKARR (Public-Key Addressable Resource Records) associates a public key with signed discovery records. In Pubky, these records connect a user’s identity to their Homeserver, so the identity can stay the same when the hosting location changes.

Finding someone without fixing their location

Section titled “Finding someone without fixing their location”

A public key is a stable identifier, but it does not tell an app which server to contact. PKARR supplies that missing step: the identity owner signs a small set of records describing where services can be reached. Those records are distributed through the Mainline DHT, a censorship-resistant, decentralized network.

For Pubky, this means an app can start with a user’s public key, discover their Homeserver, and then fetch a file. Posts and profiles stay on the Homeserver; they are not stored in the DHT.

The records use DNS’s familiar record format, but publishing an identity’s PKARR records does not require registering a conventional domain name. When hosting changes, new records can point to the new location while the public key remains the same. The signature lets clients verify who authorized a discovery record; it does not authenticate the contents of files served by that host.

Records need to be republished to remain available, and caches can delay changes. PKARR relays let browsers reach discovery services and can also help native services with limited DHT reachability. These are separate from the HTTP Relay used during app authorization.

The PKARR churn study investigates how nodes leaving the DHT affect record availability, and how replication and republishing can balance availability against network load. Its survival estimates and proposed republishing schedules describe experimental conditions, not guaranteed retention or SDK defaults. DNS record TTLs guide caching; they do not set how long DHT nodes retain a record.

Pubky app developers normally use the Pubky SDK to handle discovery. PKDNS provides a bridge for software that uses conventional DNS.

The PKARR repository maintains the detailed explanations and integration instructions: